What is the risk of non-compliance with the POPI Act Copy

What is the risk of non-compliance with POPI?

Punishable offences
– fine not exceeding R10 million or imprisonment or both:

The Act sets out a number of offences. The most applicable to a business on an operational level is:

– failure to comply with an enforcement or information notice (including making a false statement in purported compliance with an information notice);

– unlawful acts by a Responsible Party and/or Third Party in connection with an account number of a Data Subject;

– failure to notify the Regulator that Processing is subject to prior authorisation.

    Civil liability

    A Data Subject, or the Regulator at the request of the Data Subject, can institute civil action for damages against the Responsible Party.

    A Responsible Party can therefore be liable for an administrative fine and civil damages for the same offence committed.

    Administrative Fines

    The Information Regulator can impose an administrative fine (up to a maximum of R10 million) for non-compliance with the Act.

    When determining an appropriate fine, the Information Regulator must consider the following factors:

    – the nature of the Personal Information involved;

    – the duration and extent of the contravention;

    – whether the contravention raises an issue of public importance;

    – the likelihood of damage to Data Subjects;

    – whether the Responsible Party could have prevented the contravention from occurring;

    – failure to carry out a risk assessment or to operate good policies, practices and procedures to protect Personal Information; and

    – whether the Responsible Party has previously committed an offence.